谷歌称,ShinyHunters黑客组织将攻击范围扩大到了甲骨文的PeopleSoft系统

路透中文
Yesterday
<a href="https://laohu8.com/S/GOOG">谷歌</a>称,ShinyHunters黑客组织将攻击范围扩大到了<a href="https://laohu8.com/S/ORCL">甲骨文</a>的PeopleSoft系统

路透9月26日 - 谷歌网络安全部门周五表示,黑客组织ShinyHunters在绕过了今夏遭受攻击后所建立的防御措施后,再次对甲骨文(Oracle)PeopleSoft软件中的一项安全漏洞展开了“大规模利用”。

曼迪安特(Mandiant)在发布的一份威胁情报报告中披露了这一消息。此前数日,曾宣称对多起重大数据泄露事件负责的ShinyHunters组织表示,其已窃取了联邦调查局(FBI)人员数据 (link)。

此次攻击不断演变的性质,可能会让那些依赖PeopleSoft进行人力资源管理及其他关键职能运作的组织敲响警钟,并加剧人们对即使是资源雄厚的机构也存在安全漏洞的担忧。

这家隶属于Alphabet旗下 GOOGL.O Google的机构表示,ShinyHunters在5月27日至6月9日的攻击中利用了甲骨文 ORCL.N PeopleSoft企业软件中的一个漏洞,此次攻击主要影响了高校。

Mandiant表示,黑客针对5月至6月攻击事件后发布的防御指南进行了调整,将攻击目标锁定在那些虽已部署Web应用防火墙规则,但未应用甲骨文为修复该漏洞而发布的更新补丁的机构。

该公司在未透露受害者身份的情况下表示,此次最新攻击影响了全球数十个系统,涉及高等教育、科技、医疗保健、农业、交通运输和政府等多个领域。

ShinyHunters组织曾声称,他们利用PeopleSoft中的一个漏洞访问了联邦调查局(FBI)的数据。路透尚未能证实这一说法。甲骨文公司未回应置评请求。

联邦调查局(FBI)在周三发布的一份声明中表示,正在“积极调查”此次报告的数据泄露事件。

路透此前曾报道,ShinyHunters 曝光了在 FBI 敏感部门工作的员工姓名 (link),并获取了医疗和心理健康记录。

At the request of the copyright holder, you need to log in to view this content

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10